CVE-2026-26273Disclosure(withknown / known)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch withknown known systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Known is a social publishing platform. Prior to 1.6.3, a Critical Broken Authentication vulnerability exists in Known 1.6.2 and earlier. The application leaks the password reset token within a hidden HTML input field on the password reset page. This allows any unauthenticated attacker to retrieve the reset token for any user by simply querying the user's email, leading to full Account Takeover (ATO) without requiring access to the victim's email inbox. This vulnerability is fixed in 1.6.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-640

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • known

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 8 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked 5d ago at 3 mentions (2026-02-13); latest day: 1
  • 9 total mentions across 6 days

Affected systems

Vendors
Products
known

Deep dive

Activity timeline9 mentions / 6d
01223Mentions · 2026-02-13: 3Mentions · 2026-02-14: 2Mentions · 2026-02-15: 1Mentions · 2026-02-16: 1Mentions · 2026-02-18: 1Mentions · 2026-02-20: 1Patch / Workaround · 2026-02-13: 1Patch / Workaround · 2026-02-14: 1Technical Details · 2026-02-13: 3Technical Details · 2026-02-14: 2Technical Details · 2026-02-15: 1Technical Details · 2026-02-16: 1Technical Details · 2026-02-18: 102-1302-1402-1502-1602-1802-20
Signal classification3 categories
Disclosure
555.6%
Patch
222.2%
General
222.2%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-133
Disclosure2Patch1
2026-02-142
Disclosure1Patch1
2026-02-151
Disclosure1
2026-02-161
General1
2026-02-181
Disclosure1
2026-02-201
General1
Full discourse9 posts
  • anansi_oracle@sparka777
    General

    📊 CVE-2026-26273: The Over-Helpful Doorman: Full Account Takeover in 'Known' CMS: shi_gandang analy... Here's what you need to know: 1/3

    Post summary

    The text only references CVE‑2026‑26273 without providing further details such as proof‑of‑concepts, exploitation tools, or mitigation information.

    1000029
    18 followersView on X
  • anansi_oracle@sparka777
    Disclosure

    📊 CVE-2026-26273: The Over-Helpful Doorman: Full Account Takeover in 'Known' CMS: shi_gandang analy... Here's what you need to know: 1/3

    Post summary

    The snippet announces CVE‑2026‑26273 with a full account takeover flaw in a CMS, but offers no PoC, exploit code, patch, or evidence of active exploitation.

    1000034
    18 followersView on X
  • anansi_oracle@sparka777
    General

    📊 CVE-2026-26273: The Over-Helpful Doorman: Full Account Takeover in 'Known' CMS: shi_gandang analy... Here's what you need to know: 1/3

    Post summary

    The tweet references CVE-2026-26273 as a full account takeover vulnerability in a known CMS, but offers no PoC, exploit details, patch information, or evidence of active exploitation.

    1000043
    18 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-26273 Critical Broken Authentication Vulnerability in Known Platform Versions 1.6.2 and Earlier https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26273

    Post summary

    CVE-2026-26273 is a critical broken authentication vulnerability affecting platform versions 1.6.2 and earlier; the text provides a disclosure with no PoC, exploit, or patch information.

    0001023
    4.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-26273 Known is a social publishing platform. Prior to 1.6.3, a Critical Broken Authentication vulnerability exists in Known 1.6.2 and earlier. The application leaks the pas… https://www.cve.org/CVERecord?id=CVE-2026-26273

    Post summary

    The CVE describes a critical broken authentication vulnerability in Known versions 1.6.2 and earlier, resolved by upgrading to version 1.6.3.

    00010407
    56.5K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-26273: Known affected by Account Takeov... Rookie mistake: Known devs exposed reset tokens in HTML source, enabling trivial account takeover with just an email ad... https://zerodaysignal.com/vulnerability/CVE-2026-26273 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE-2026-26273, noting that reset tokens are exposed in HTML and allowing trivial account takeover, but provides no patch or exploit details.

    0000046
    131 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: CVE-2026-26273 in Known <1.6.3 exposes password reset tokens, enabling full account takeover — no email access needed! Patch to 1.6.3 ASAP. 🔒 https://radar.offseq.com/threat/cve-2026-26273-cwe-200-exposure-of-sensitive-infor-d59f1dbb #OffSeq #CVE202626273 #Infosec https://t.co/9zmd3sjy1R

    Post summary

    The tweet highlights a critical flaw (CVE‑2026‑26273) that leaks password reset tokens for account takeover and urges users to update to version 1.6.3 immediately.

    0000043
    268 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-26273: The Over-Helpful Doorman: Full Account Takeover in 'Known' CMS CVE-2026-26273 is a catastrophic logic flaw in the 'Known' social publishing platform that turns the password reset mechanism into an open buffet for attackers. By simply k... https://cvereports.com/reports/CVE-2026-26273

    Post summary

    CVE‑2026‑26273 is a logic flaw in the Known CMS that exploits the password reset workflow, enabling attackers to perform full account takeover.

    0000044
    27 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-26273 - Critical Known is a social publishing platform. Prior to 1.6.3, a Critical Broken Authentication vulnerability exists in Known 1.6.2 and earlier. The application leaks the password reset token wit... https://www.thehackerwire.com/vulnerability/CVE-2026-26273/ https://t.co/FB2hCjmpsN

    Post summary

    The text announces a critical CVE-2026-26273 affecting Known 1.6.2 and earlier, describing a broken authentication flaw that leaks password reset tokens.

    0000060
    112 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwithknownknown---

Explore more